unsloth/.github
LeoBorcherding 48b5eb1a14 tests: pin the amd/huggingfacenotorch extras and name the audit failure
security-audit.yml builds its hf-stack scan set by indexing
[huggingfacenotorch] out of pyproject.toml with no guard. The pip release
branch never had that extra, so advisory audit and the three pip
scan-packages jobs died on a bare KeyError from at least 2026-07-08 to
2026-07-27 without anyone reading it as a missing extra.

Add a contract test for both extras (existence, torch-free, bnb floor
excludes the NaN-at-decode range) plus a check that every extra the
workflow indexes actually exists, and give the workflow a message that
names the problem instead of a raw traceback.
2026-07-28 00:40:49 -05:00
..
ISSUE_TEMPLATE Update issue template 2026-03-23 10:10:15 +05:30
scripts Studio: clarify tool permission controls (#7181) 2026-07-20 09:55:39 -03:00
workflows tests: pin the amd/huggingfacenotorch extras and name the audit failure 2026-07-28 00:40:49 -05:00
CODEOWNERS Update CODEOWNERS 2026-06-10 11:09:16 -07:00
dependabot.yml security: NOT affected by Mini Shai-Hulud (May-12 wave) -- forward-looking hardening only (#5397) 2026-05-13 04:58:12 -07:00
FUNDING.yml Update FUNDING.yml (#3792) 2025-12-28 19:57:43 -08:00